
Research
2025 Report: Destructive Malware in Open Source Packages
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.
aws-sso-cred-restore
Advanced tools
A wrapper for executing a command with AWS CLI v2 and SSO, inspired from aws2-wrap
This is script is inspired from aws2-wrap and solve problem with old sdk's like aws-sdk-go and turn safe our
work with tools like terraform.
Work with terraform is more safe if we use only profile configuration and work with workspaces feature.
provider "aws" {
profile = "${terraform.env}"
region = "${var.region}"
}
But aws sso cli command cannot configure credentials file, and aws-sdk-go cannot work with new model of profile config.
Using environment variables, the configuration overwrite profile option on provider block on terraform, and this is dangerous.
This wrapper solve temporary (hello aws and hashicorp, solve this plis!!) this problem.
piphttps://pypi.org/project/aws-sso-cred-restore
pip install aws-sso-cred-restore==<VERSION>
aws-sso-cred-restore --profile <awsprofilename-or-prefix>
or run to all profiles in your config
aws-sso-cred-restore
This command will get credentials using active aws sso access key section file
and restore in ~/.aws/credentials
There may be circumstances when it is easier/better to set the appropriate environment variables so that they can be re-used by any aws command.
Since the script cannot directly set the environment variables in the calling shell process, it is necessary to use the following syntax:
eval "$(aws-sso-cred-restore --profile <awsprofilename-or-prefix> --export)"
FAQs
A wrapper for executing a command with AWS CLI v2 and SSO, inspired from aws2-wrap
We found that aws-sso-cred-restore demonstrated a healthy version release cadence and project activity because the last version was released less than a year ago. It has 1 open source maintainer collaborating on the project.
Did you know?

Socket for GitHub automatically highlights issues in each pull request and monitors the health of all your open source dependencies. Discover the contents of your packages and block harmful activity before you install or update your dependencies.

Research
Destructive malware is rising across open source registries, using delays and kill switches to wipe code, break builds, and disrupt CI/CD.

Security News
Socket CTO Ahmad Nassri shares practical AI coding techniques, tools, and team workflows, plus what still feels noisy and why shipping remains human-led.

Research
/Security News
A five-month operation turned 27 npm packages into durable hosting for browser-run lures that mimic document-sharing portals and Microsoft sign-in, targeting 25 organizations across manufacturing, industrial automation, plastics, and healthcare for credential theft.